Live data from Hacker News

We found a stable Firefox identifier linking all your private Tor identities

fingerprint.com

71–80 of 306 posts

Re: We found a stable Firefox identifier linking all your private Tor identities

#71
post #37
post #10

From the sounds of this it sounds like it doesn't persist past browser restart? I think that would significantly reduce the usefulness to attackers.

Many users leave their browsers open for months.

Privacy and security conscious Tor users don’t.

Re: We found a stable Firefox identifier linking all your private Tor identities

#72
post #54

I question why websites can even access all this info without asking or notifying the user. Why don't browsers make it like phones where the server (app) has to be granted permission to access stuff?

>Why don't browsers make it like phones where the server (app) has to be granted permission to access stuff? Like Android phones perhaps? Unfortunate Apple gives very little granular control.

Most stock android phones don't either. You usually get to control precise location, notifications, some background activity, SMS, Calls, Mic, Camera, SD Card, etc.

But most ROMs don't allow controls for WiFi, Cell data, Phone ID, Phone number, User ID, local storage, etc...

Re: We found a stable Firefox identifier linking all your private Tor identities

#73
post #25

I'm confused. The IndexedDB UUID is "shared across all origins", so why not use the contents of the database to identify browers, rather than the ordering?

There's an instructive example on the page. Suppose a page creates the databases `a,b,c,d,e,f,g,h,i,j,k,l,m,n,o,p`, then queries their order. They might get, for example `g,c,p,a,l,f,n,d,j,b,o,h,e,m,i,k`, based on the global mapping of database names to UUIDs. The key vulnerability here is that, for the lifetime of that Firefox process, any website that makes that set of databases is going to see the exact same outpu…

As I understood not ANY website can see it. But the same website can see it regardless if you reset your identity in Tor Browser.

So it persists between anonymous sessions. So you could connect User A that logged out and reset the identity to User B who believed was using a fresh anonymous session and logged in afterwards.

Re: We found a stable Firefox identifier linking all your private Tor identities

#74

Earlier quoted context omitted.

Uhh okay, so they do exploit vulnerabilities, they just try to target victims who can be served ads? What a weird distinction.

Painting fingerprinting as vulnerability exploit is your own very biased and very out-of-norm framing.

Instead of trying convince-by-assertion, maybe you could try offering an actual objection to the argument raised up-thread?

On what basis do you claim that software developers, who did not establish a means of for third parties to get a stable identifier, nevertheless intended that fingerprinting techniques should work?

Re: We found a stable Firefox identifier linking all your private Tor identities

#75
post #52

I question why websites can even access all this info without asking or notifying the user. Why don't browsers make it like phones where the server (app) has to be granted permission to access stuff?

The most popular browser is made by an ad company. They also provide the majority of funding for their biggest competitor. Why would you expect anything different?

most people would expect something different from tor, surely.

Re: We found a stable Firefox identifier linking all your private Tor identities

#76

Earlier quoted context omitted.

So it's the criminal that convinced themselves they are the good guys, I didn't expect that one. You are a malware company get a grip.

Responsible disclosure and commercial fingerprinting aren't contradictory.

[flagged]

Re: We found a stable Firefox identifier linking all your private Tor identities

#77

Earlier quoted context omitted.

Would you prefer that they kept this for themselves instead of disclosing it? I get criticizing their business and what they do wrong, but doesn't seem right to criticizing them for doing the right thing.

It means they are suspect. I think its right to be wary of motives if they are involved in the very thing they aim to bring awareness too. Questions arise in my mind as to why they would do something like this in the first place. Its been my experience that the general public doesn't seem to follow patterns and instead focus on which switch is toggled at any given moment for a company's ethical practices. This is the…

I don't trust them more because of this and maybe they've disclosed it for the wrong reasons, like not allowing a competitor to use it when they don't, but at the end of the day they did disclose a serious issue, and that's good for users.

I understand where you're coming from, by the way, but sometimes the worst person you know does the right thing and it's not fair to criticize them for doing it (you could say nothing, don't have to change your opinion about them, etc). We also don't want someone to go "if I'm bad no matter what I do, then might as well make some money with this" and sell the exploit.

Re: We found a stable Firefox identifier linking all your private Tor identities

#79

Earlier quoted context omitted.

So it's the criminal that convinced themselves they are the good guys, I didn't expect that one. You are a malware company get a grip.

Would you prefer that they kept this for themselves instead of disclosing it? I get criticizing their business and what they do wrong, but doesn't seem right to criticizing them for doing the right thing.

What are you even saying? It's like getting upset at somebody who criticizes a criminal because they once helped some grandma across the street. I'm not upset at the criminal because they helped a grandma across the street obviously that's not the fucking point.

Re: We found a stable Firefox identifier linking all your private Tor identities

#80

Earlier quoted context omitted.

Painting fingerprinting as vulnerability exploit is your own very biased and very out-of-norm framing.

Instead of trying convince-by-assertion, maybe you could try offering an actual objection to the argument raised up-thread? On what basis do you claim that software developers, who did not establish a means of for third parties to get a stable identifier, nevertheless intended that fingerprinting techniques should work?

There's a pretty big difference between:

1) wanting functionality that isn't provided and working around that

and

2) restoring such functionality in the face of countermeasures

The absence of functionality isn't a clear signal of intent, while countermeasures against said functionality is.

And then there is the distinction between the intent of the software publisher and the intent of the user. There is a big ethical difference between "Mozilla doesn't want advertisers tracking their users" and "those users don't want to be tracked". If these guys want to draw the line at "if there is a signal from the user that they want privacy, we won't track them", I think that's reasonable.

Post reply on HN